|
210101
|
6.1 |
MEDIUM
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
By exploiting an Open Redirect vulnerability on a website, an attacker could have spoofed the site displayed in the download file dialog to show the original site (the one suffering from the open red…
|
CWE-601
Open Redirect
|
CVE-2020-15677
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210102
|
6.1 |
MEDIUM
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
Firefox sometimes ran the onload handler for SVG elements that the DOM sanitizer decided to remove, resulting in JavaScript being executed after pasting attacker-controlled data into a contenteditabl…
|
CWE-79
Cross-site Scripting
|
CVE-2020-15676
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210103
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
When processing surfaces, the lifetime may outlive a persistent buffer leading to memory corruption and a potentially exploitable crash. This vulnerability affects Firefox < 81.
|
CWE-416
Use After Free
|
CVE-2020-15675
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210104
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
Mozilla developers reported memory safety bugs present in Firefox 80. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
|
CWE-787 CWE-667
Out-of-bounds Write Improper Locking
|
CVE-2020-15674
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210105
|
8.8 |
HIGH
Network
|
mozilla debian opensuse
|
firefox_esr thunderbird firefox debian_linux leap
|
Mozilla developers reported memory safety bugs present in Firefox 80 and Firefox ESR 78.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these…
|
CWE-416
Use After Free
|
CVE-2020-15673
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210106
|
3.1 |
LOW
Network
|
mozilla
|
firefox
|
When typing in a password under certain conditions, a race may have occured where the InputContext was not being correctly set for the input field, resulting in the typed password being saved to the …
|
CWE-200 CWE-362
Information Exposure Race Condition
|
CVE-2020-15671
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210107
|
8.8 |
HIGH
Network
|
mozilla
|
firefox firefox_esr thunderbird
|
Mozilla developers reported memory safety bugs present in Firefox for Android 79. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could ha…
|
CWE-362 CWE-416 CWE-617
Race Condition Use After Free Reachable Assertion
|
CVE-2020-15670
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210108
|
8.8 |
HIGH
Network
|
mozilla
|
firefox_esr thunderbird
|
When aborting an operation, such as a fetch, an abort signal may be deleted while alerting the objects to be notified. This results in a use-after-free and we presume that with enough effort it could…
|
CWE-416
Use After Free
|
CVE-2020-15669
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210109
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
A lock was missing when accessing a data structure and importing certificate information into the trust database. This vulnerability affects Firefox < 80 and Firefox for Android < 80.
|
CWE-667
Improper Locking
|
CVE-2020-15668
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210110
|
8.8 |
HIGH
Network
|
mozilla
|
firefox
|
When processing a MAR update file, after the signature has been validated, an invalid name length could result in a heap overflow, leading to memory corruption and potentially arbitrary code executio…
|
CWE-787
Out-of-bounds Write
|
CVE-2020-15667
|
2024-11-21 14:05 |
2020-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|